Password Reset Vulnerability in SysReptor Pentest Reporting Platform
CVE-2026-81179
What is CVE-2026-81179?
The SysReptor Pentest Reporting Platform has a vulnerability where prior to version 2026.58, installations that allow password resets via email with a misconfigured ALLOWED_HOSTS setting can be exploited. An attacker can manipulate the Host header during the password reset process to redirect the victim to an attacker-controlled domain. This scenario enables an unauthenticated attacker to obtain a password reset link containing a sensitive token, allowing them to reset the victim's password and gain unauthorized access to the account. Proper email gateway configuration and potential misconfigurations in reverse proxy setups can influence the effectiveness of this attack. The issue has been resolved in version 2026.58, highlighting the importance of strict validation of Host headers.
Affected Version(s)
sysreptor < 2026.58
